Re: [OAUTH-WG] [DPoP] Protected resource access and invalid DPoP proofs

2021-08-11 Thread Dmitry Telegin
Sorry, "Basic" should be "Bearer" obviously. Dmitry On Thu, Aug 12, 2021 at 12:02 AM Dmitry Telegin wrote: > Hi Brian, thanks for the response, > > On a related note, chapter 7.2 allows for protected resources supporting > Bearer and DPoP schemes simultaneously. Is it implied that such resources

Re: [OAUTH-WG] [DPoP] Protected resource access and invalid DPoP proofs

2021-08-11 Thread Dmitry Telegin
Hi Brian, thanks for the response, On a related note, chapter 7.2 allows for protected resources supporting Bearer and DPoP schemes simultaneously. Is it implied that such resources should advertise both schemes when challenging user agents with WWW-Authenticate? The HTTP 1.1 Authentication spec,